Compliance. Not theater.

Blue Reacher sits between your CRM and your customer's phone. This page publishes practices, agreements and the vendor list rather than badges.

Ten claims, every one backed by a document you can open right now

Every badge above links to the section that expands it, and every one of those sections links the document behind the claim. Compare that to the badge rows on the rest of this category, which link nowhere.

Every claim carries proof

Each row links the document behind it. Where a third party's signature is missing, this page says so.

GDPRReady
Blue Reacher acts as processor and you act as controller. A data processing agreement is published in full, standard contractual clauses cover transfers, and data subject access, correction, erasure, portability and objection requests are handled inside 30 days. Read the detail
CCPA and CPRAReady
California residents can request access, correction, deletion and a record of disclosure. Blue Reacher sells no personal information and shares none for cross-context behavioural advertising, so there is no opt-out of sale to build because there is no sale. Read the detail
TCPACompliant
Opt-outs are detected automatically, honored immediately, and enforced at the platform rather than inside your sequence logic. Suppression cannot be overridden over the API, every enforcement event is logged, and the consent and list rules we hold customers to are published in full. Read the detail
HIPAABAA available
No authority issues a HIPAA certificate. What makes the claim real is a signed business associate agreement, and Blue Reacher signs one on Enterprise plans. The controls that agreement rests on, encryption, access logging, retention limits and verified deletion, are listed below. Read the detail
PCI DSSSAQ-A
Card data never touches Blue Reacher systems. Payment pages are hosted entirely by Stripe, a PCI DSS Level 1 service provider, which puts Blue Reacher in the SAQ-A category: the smallest scope the standard defines. Read the detail
SOC 2Aligned controls
Blue Reacher's controls are mapped to the SOC 2 Trust Services Criteria for security, availability and confidentiality, and the mapping is handed over on request rather than described. What Blue Reacher will not do is print a seal it has not earned: the independent attestation has not been completed and this page says so, which is more than you get from the two platforms in this category displaying a SOC 2 badge with no report behind it. Read the detail
AES-256At rest
Stored data, including contact records and message history, is encrypted at rest with AES-256. Keys are managed through the cloud provider's key management service and are never held in application code. Read the detail
TLS 1.3In transit
Traffic between your browser, your CRM and Blue Reacher is encrypted with TLS 1.3, falling back no lower than 1.2. API access is authenticated with per-customer bearer keys you rotate yourself, without asking us. Read the detail
MFAEnforced
Multi-factor authentication is required on every account with access to production systems, with no exemptions and no shared logins. Access is least-privilege, reviewed on a schedule, and every touch of production data writes an audit entry. Read the detail
Data residencyUnited States
Customer data is stored and processed in United States infrastructure. Production, staging and development are isolated from one another, and internal tooling is never exposed publicly. Read the detail

Disclosure beats badges

Blue Reacher publishes the DPA, names every subprocessor, answers 15 security-review questions, and states gaps plainly. The controls are contractually binding in writing today.

Controls, in the categories reviewers ask about

Security reviews arrive in the same six shapes almost every time, so the answers are grouped the way the questionnaire groups them. A fuller control mapping against the SOC 2 Trust Services Criteria goes out on request.

Access control
Role-based least-privilege access, no standing access, MFA required, audit logs retained 90+ days.
Infrastructure security
US cloud infrastructure. Production, staging and development isolated. Zero-downtime deployments with automated rollback.
Data protection
TLS 1.3 in transit, AES-256 at rest. Workspaces logically isolated. Automated backups with verified integrity.
Incident response
Documented response plan. Breach notification within 48 hours, aligned to GDPR Article 33.
Vendor management
Every subprocessor reviewed and carries DPA protections. List published at /subprocessors. 30 days notice on changes.
Application security
Code review before production. Dependency scanning. Secrets in vaults, never in source control.

Posture reviewed November 10, 2025

Pre-answered security review questions

What can a security reviewer read before signing?

Controls mapped to the SOC 2 Trust Services Criteria for security, availability and confidentiality, the signed DPA, the subprocessor list, and a completed security questionnaire. The full control mapping goes out on request.

Will Blue Reacher sign a DPA?

Yes. Published in full at /dpa. Standard contractual clauses cover transfers out of the US.

Will Blue Reacher sign a BAA for protected health information?

Yes, on Enterprise plans. Controls include encryption in transit/at rest, least-privilege access with audit logging, and verified deletion.

Where is customer data stored?

US cloud infrastructure. Production, staging and development isolated. Workspaces logically isolated by account.

How is data encrypted?

TLS 1.3 in transit (fallback TLS 1.2), AES-256 at rest. Keys managed by cloud provider.

Who inside Blue Reacher can see customer messages?

Least-privilege access, MFA required, no standing access. All access logged, 90+ day retention.

Is customer data used to train AI models?

No. Data never sold, shared between customers or used for public AI training. Anonymized metrics only.

What happens to our data when we leave?

Request deletion or export anytime. Deletion within 30 days. Data retained 90 days post-termination for exports.

Who are the subprocessors?

Full list at /subprocessors with purpose, data category and region. 30 days notice on changes.

How quickly are breaches reported?

Within 48 hours of discovery, aligned to GDPR Article 33. Notification includes nature, data categories and remediation.

Does Blue Reacher handle card data?

No. Stripe hosts payments (PCI DSS Level 1). Blue Reacher is in SAQ-A category.

How are opt-outs enforced?

Automatic detection, immediate enforcement, permanent account-wide. Suppression cannot be overridden via API.

Does Blue Reacher offer single sign-on?

Not today. Per-user credentials with MFA available. API uses rotatable per-customer bearer tokens.

What does support look like?

24/7 and 1:1 on Slack, on every plan, with the team that builds the funnels. No ticket queue, no tiers.

How do we report a vulnerability?

Email support@bluereacher.com or use /.well-known/security.txt. Coordinated disclosure welcome, good-faith researchers credited.

Not answered here?

Send your questionnaire and get back the control mapping, subprocessor list and countersigned DPA the same week. support@bluereacher.com